|
211891
|
5.9 |
MEDIUM
Network
|
blackberry
|
athoc
|
An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary loca…
|
CWE-611
XXE
|
CVE-2019-8997
|
2024-11-21 13:50 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211892
|
6.1 |
MEDIUM
Network
|
humhub
|
humhub
|
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in /s/adada/cfiles/upload in Humhub 1.3.10 Community Edition. The user-supplied input containing JavaScript in the filename is echo…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9094
|
2024-11-21 13:50 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211893
|
6.1 |
MEDIUM
Network
|
humhub
|
humhub
|
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in file/file/upload in Humhub 1.3.10 Community Edition. The user-supplied input containing a JavaScript payload in the filename par…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9093
|
2024-11-21 13:50 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211894
|
9.8 |
CRITICAL
Network
|
sqlitemanager
|
sqlitemanager
|
SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is discontinued.
|
CWE-89
SQL Injection
|
CVE-2019-9083
|
2024-11-21 13:50 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211895
|
6.1 |
MEDIUM
Network
|
vertrigoserv_project
|
vertrigoserv
|
VertrigoServ 2.17 allows XSS via the /inc/extensions.php ext parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8938
|
2024-11-21 13:50 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211896
|
3.3 |
LOW
Local
|
qemu opensuse
|
qemu leap
|
hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2019-8934
|
2024-11-21 13:50 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211897
|
7.7 |
HIGH
Network
|
tibco
|
jasperreports_server
|
The SOAP API component vulnerability of TIBCO Software Inc.'s TIBCO JasperReports Server, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that may allow a malicious authe…
|
NVD-CWE-noinfo
|
CVE-2019-8986
|
2024-11-21 13:50 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211898
|
6.1 |
MEDIUM
Network
|
wuzhicms
|
wuzhicms
|
XSS exists in WUZHI CMS 4.1.0 via index.php?m=core&f=map&v=baidumap&x=[XSS]&y=[XSS] to coreframe/app/core/map.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9108
|
2024-11-21 13:50 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211899
|
6.1 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
XSS exists in WUZHI CMS 4.1.0 via index.php?m=attachment&f=imagecut&v=init&imgurl=[XSS] to coreframe/app/attachment/imagecut.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9107
|
2024-11-21 13:50 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211900
|
8.8 |
HIGH
Network
|
thinkphp opensourcebms zzzcms
|
thinkphp open_source_background_management_system zzzphp
|
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=syste…
|
CWE-94 CWE-306
Code Injection Missing Authentication for Critical Function
|
CVE-2019-9082
|
2024-11-21 13:50 |
2019-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|